Configure UEBA

UEBA Overview

UEBA in Director Console is a security solution that helps you configure UEBA in Fabric-enabled LogPoint. It helps you manage potential breaches efficiently and provides you with the tools to analyze the detected anomalies.

UEBA dashboard includes License, Overview, Entity Selection, and Settings.You can set a proper baseline in UEBA which requires a minimum of 30 days of historical data. If you want to enable UEBA today, you need appropriately normalized and enriched input logs of at least 30 days.

You can enable UEBA, add the UEBA license, and select the repos and entities for UEBA analysis from the UEBA page. You can also view the health status of the system.

chevron-rightInstall UEBA Licensehashtag

You need a valid UEBA license to configure Fabric-enabled LogPoint. The license contains the UEBA validity period, the number of entities you can monitor, and the Client Configuration file necessary for UEBA configuration. Contact the vendor for more details on the configuration file.

Adding a License

Before adding a license, contact the vendor to provide your Hardware Key. The vendor then sends you the license file based on the number of entities you want to monitor using UEBA. Once you receive a valid license file, follow the steps below to add the license:

  1. Go to Configure >> Settings and click UEBA.

  2. Select a machine and click Next.

  3. Select License.

  4. Click to upload or drag and drop the license.

  5. Browse and upload the license key.

  6. Click Next.

  7. Review your changes. You can go Back to update the configuration if necessary.

  8. Click Finish.

  9. Click Ok to install the UEBA license.

chevron-rightEnable UEBA Licensehashtag

You can enable/disable UEBA in the selected Fabric-enabled LogPoint and see the health status of the system from the Overview page. However, you must upload the License before enabling UEBA.

  1. Go to Configure >> Settings and click UEBA.

  2. Select Overview.

  3. Check Enable UEBA.

  4. Click Next.

  5. Review your changes. You can go Back to update the configuration if necessary.

  6. Click Finish.

  7. Click Ok to enable UEBA.

circle-info

You can Download Report to save the task summary in .pdf.

chevron-rightHealth Statushashtag

The Health Status section includes:

  1. The number of days UEBA has been enabled in Director.

  2. The number of Active Directory logs sent for UEBA analysis in the last 24 hours.

  3. The number of web proxy logs sent for UEBA analysis in the last 24 hours.

  4. The number of email logs sent for UEBA analysis in the last 24 hours.

  5. The number of VPN logs sent for UEBA analysis in the last 24 hours.

  6. The number of authentication logs sent for UEBA analysis in the last 24 hours.

  7. The number of resource access logs sent for UEBA analysis in the last 24 hours.

  8. The number of sap authentication logs sent for UEBA analysis in the last 24 hours.

Health Status
chevron-rightValidation Summaryhashtag

The Validation Summary section contains:

  1. The total number of historical and real-time logs analyzed for data validation in the last two days.

  2. The total number of invalid logs detected in the last two days while running the validation.

  3. The total number of invalid logs found according to the different data sources.

UEBA Validation Summary

Managing UEBA Entities

circle-check

You can add, edit, and delete the entities for UEBA to monitor on the Entity Selection page. It shows:

  • The total number of licensed entities.

  • The total number of entities set for threat analysis.

  • The specifics of the configured entities.

  • The total number of users and machines chosen.

chevron-rightAdd UEBA Entitieshashtag
  1. Go to Configure >> Settings and click UEBA.

  2. Select Entity Selection.

  3. In Add Entity:

    1. Enter the Group Name.

    2. Select a Group Type, either User or Machine. If you select Machine, choose whether the source contains the CIDR, the Hostname, or the IP address of the machine.

  4. In Enrichment Source, enter the source name to search the enrichment source.

  5. In the Enrichment Source section, select a specific enrichment source from the given list. It can be LDAP, CSV, or ODBC.

  6. In Select Unique Identifier For Entities, select the identifier from the drop-down. It is automatically provided as per the selected Enrichment Source.

  7. In Entities Filtering:

    1. Select a Field from the drop-down.

    2. Enter a Query. It is a parameter for filtering the enrichment source.

  8. Enable Update The Licensed Entity When The Content In The Source Is Changed.

  9. Click ADD ENTITY.

  10. Click Next.

  11. Review your changes. You can go Back to update the configuration if necessary.

  12. Click Finish.

circle-info

You can Download Report to save the task summary in .pdf.

chevron-rightEdit UEBA Entitieshashtag
  1. Go to Configure >> Settings and click UEBA.

  2. Select Entity Selection.

  3. Click the entity you want to edit.

  4. Make the necessary changes in all three panels.

  5. Click EDIT ENTITY.

  6. Click Next.

chevron-rightDelete UEBA Entitieshashtag
  1. Go to Configure >> Settings and click UEBA.

  2. Select Entity Selection.

  3. Click the Cross icon on the right end of the entity.

chevron-rightPrioritize UEBA Entitieshashtag

UEBA process the prioritized entities based on Number of Entities Licensed.

  1. Go to Configure >> Settings and click UEBA.

  2. Select Entity Selection.

  3. Drag and drop the entity to re-order.

Configuring UEBA Settings

You can choose the LogPoint Search Head and Distributed LogPoint instances repositories for UEBA analysis in Fabric-enabled LogPoint instances from the Settings page. Similarly, you can enable or disable the history service.

chevron-rightSelect Reposhashtag

You can select multiple repositories from the drop-down in the Repos section. The repos in the Repo Selector are grouped by Distributed LogPoint instances (DLP) or Repo.

  1. In Select Repos:

    1. Check Select Repos to choose all the repos of all machines.

    2. Check All Repos to choose all the repos of a machine.

    3. Click the All Repos drop-down to select specific repos for a machine.

  2. Click Next.

  3. Review your changes. You can go Back to update the configuration if necessary.

  4. Click Finish.

  5. Click Ok.

circle-info

You can Download Report to save the task summary in .pdf.

chevron-rightEnable the History Servicehashtag

Enable the history service for a better baseline and result. You can enable the history service only once for a machine.You can enable the history service to send 30 days of historical data to UEBA.

  1. Go to Configure >> Settings and click UEBA.

  2. Select Settings.

  3. Select the Enable History Service checkbox.

chevron-rightSet the Risk Scorehashtag
  1. Go to Configure >> Settings and click UEBA.

  2. Select Settings.

  3. In Risk Score, set the value of the risk score by dragging the slider.

Last updated

Was this helpful?